300-435 Question 177
Single answerAn enterprise network is using Cisco SD-Access (SDA) to simplify management and enhance security. The network administrator plans to deploy a new group-based policy to control communication between two user groups. Which critical component of SDA must be configured to enforce this policy?
- A
Cisco DNA Center
- B
Identity Services Engine (ISE)
- C
Fabric Border Node
- D
LISP Control Plane
Show answer and explanation
Correct answer: B
Explanation
In Cisco SD-Access, group-based policies are enforced through Cisco Identity Services Engine (ISE). ISE integrates with the SDA fabric to authenticate users and devices, assign them to scalable groups, and apply policies that govern communication between these groups. While other components like Cisco DNA Center and the Fabric Border Node play essential roles in SDA, only ISE directly enforces group-based policies.
- A. Incorrect.
Cisco DNA Center is responsible for orchestrating and managing the SDA fabric, but it does not directly enforce group-based policies. It works in conjunction with ISE for policy configuration.
- B. Correct.
Identity Services Engine (ISE) is critical for enforcing group-based policies in Cisco SDA. ISE handles user identity authentication and applies segmentation policies based on group membership.
- C. Incorrect.
The Fabric Border Node provides connectivity between the SDA fabric and external networks but does not enforce group-based policies.
- D. Incorrect.
LISP (Locator/ID Separation Protocol) is used as the control plane in SDA for endpoint tracking and communication within the fabric, but it does not manage or enforce group-based policies.